Skip to slide
Chapter 11 · Security, Auth, and Multi-Tenancy
102 / 191

CHAPTER 11 · Security, Auth, and Multi-Tenancy · 4 / 9

Application-layer authorization vs database RLS

Two places to enforce authorization:

  • Database row-level security (RLS): the database itself filters rows by the current user. Strong because it's enforced at the lowest layer, but it requires the user identity to reach the database and ties you to that DB's RLS features.
  • Application-layer checks: the backend is the only thing that talks to the database (with a privileged connection), and it enforces access via the centralized helpers.

Both are valid. The application-layer approach is common for agents because the browser never touches the database directly: all access flows through the backend, so a disciplined set of access helpers is your row-level security. Its strength is explicitness and testability (the logic is in code you can read in full); its risk is discipline (forget a check on a new route and you have a hole). If you take this path, make the access helpers the only sanctioned way to load shared resources, and review every new route for them.

← → arrow keys work too